Logfile of HijackThis v1.99.1
Scan saved at 19:19:19, on 21/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SLEE81.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\CyberLink\PowerVCRII\Agent.exe
C:\WINDOWS\system32\JupitCo.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\WINDOWS\DitExp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\dlpmon32.exe
C:\WINDOWS\system32\nthk.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\dpalsrv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\blcorp\UWCSuite\WinMem\WinMem.exe
C:\WINDOWS\system32\dlptools.exe
C:\Program Files\DESkey\DESlock+\dlpfe.exe
C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
C:\Program Files\BigFix\BigFix.exe
C:\freeserve\freeserveconnectionkit\atdialler1.exe
C:\Program Files\Aladdin Systems\Internet Cleanup\onictask.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\MRU-Blaster\scheduler.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Star Downloader\stardown.exe
C:\Program Files\a2\a2start.exe
C:\Program Files\a2\a2cfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\me\My Documents\HJT\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\fnsds.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\fnsds.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.talktalk.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\fnsds.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\fnsds.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\fnsds.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.talktalk.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\fnsds.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {02DA43E3-4040-4537-5E7E-2E3A20068395} - C:\WINDOWS\system32\ntnb32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Class - {F3C3DC70-25D1-3C6C-E10B-C6BF822AC5DA} - C:\WINDOWS\system32\syswh.dll
O2 - BHO: Class - {F60FA6C9-5178-D041-061D-CC3DFBD00791} - C:\WINDOWS\system32\sdkgv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Agent] C:\Program Files\CyberLink\PowerVCRII\Agent.exe
O4 - HKLM\..\Run: [USB SECURITY DEVICE CoInstaller] JupitCo.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [DESlock+ Startup (Warning: Removal of this will disable DESlock+)] dlpmon32.exe
O4 - HKLM\..\Run: [crqm.exe] C:\WINDOWS\system32\crqm.exe
O4 - HKLM\..\Run: [nthk.exe] C:\WINDOWS\system32\nthk.exe
O4 - HKLM\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
O4 - HKLM\..\Run: [appiw32.exe] C:\WINDOWS\appiw32.exe
O4 - HKLM\..\RunOnce: [crsv.exe] C:\WINDOWS\system32\crsv.exe
O4 - HKLM\..\RunOnce: [apivg32.exe] C:\WINDOWS\system32\apivg32.exe
O4 - HKLM\..\RunOnce: [javawl.exe] C:\WINDOWS\javawl.exe
O4 - HKLM\..\RunOnce: [iexc.exe] C:\WINDOWS\iexc.exe
O4 - HKLM\..\RunOnce: [ient32.exe] C:\WINDOWS\system32\ient32.exe
O4 - HKLM\..\RunOnce: [msxp.exe] C:\WINDOWS\msxp.exe
O4 - HKLM\..\RunOnce: [sysnb32.exe] C:\WINDOWS\system32\sysnb32.exe
O4 - HKLM\..\RunOnce: [wingw.exe] C:\WINDOWS\wingw.exe
O4 - HKLM\..\RunOnce: [netxp.exe] C:\WINDOWS\netxp.exe
O4 - HKLM\..\RunOnce: [appqt32.exe] C:\WINDOWS\appqt32.exe
O4 - HKLM\..\RunOnce: [appfo.exe] C:\WINDOWS\system32\appfo.exe
O4 - HKLM\..\RunOnce: [addoo.exe] C:\WINDOWS\addoo.exe
O4 - HKLM\..\RunOnce: [apiip.exe] C:\WINDOWS\apiip.exe
O4 - HKLM\..\RunOnce: [appyj32.exe] C:\WINDOWS\system32\appyj32.exe
O4 - HKLM\..\RunOnce: [javakw32.exe] C:\WINDOWS\system32\javakw32.exe
O4 - HKLM\..\RunOnce: [atliw32.exe] C:\WINDOWS\system32\atliw32.exe
O4 - HKLM\..\RunOnce: [msny.exe] C:\WINDOWS\system32\msny.exe
O4 - HKLM\..\RunOnce: [apilz.exe] C:\WINDOWS\system32\apilz.exe
O4 - HKLM\..\RunOnce: [winqt32.exe] C:\WINDOWS\winqt32.exe
O4 - HKLM\..\RunOnce: [atlvy.exe] C:\WINDOWS\system32\atlvy.exe
O4 - HKLM\..\RunOnce: [msas32.exe] C:\WINDOWS\system32\msas32.exe
O4 - HKLM\..\RunOnce: [appks32.exe] C:\WINDOWS\appks32.exe
O4 - HKLM\..\RunOnce: [mspn32.exe] C:\WINDOWS\system32\mspn32.exe
O4 - HKLM\..\RunOnce: [d3dj.exe] C:\WINDOWS\d3dj.exe
O4 - HKLM\..\RunOnce: [iprm.exe] C:\WINDOWS\iprm.exe
O4 - HKLM\..\RunOnce: [msrg.exe] C:\WINDOWS\msrg.exe
O4 - HKLM\..\RunOnce: [ipwa32.exe] C:\WINDOWS\ipwa32.exe
O4 - HKLM\..\RunOnce: [apigj.exe] C:\WINDOWS\apigj.exe
O4 - HKLM\..\RunOnce: [sysld32.exe] C:\WINDOWS\system32\sysld32.exe
O4 - HKLM\..\RunOnce: [ipjb.exe] C:\WINDOWS\system32\ipjb.exe
O4 - HKLM\..\RunOnce: [appoe32.exe] C:\WINDOWS\system32\appoe32.exe
O4 - HKLM\..\RunOnce: [d3ix32.exe] C:\WINDOWS\system32\d3ix32.exe
O4 - HKLM\..\RunOnce: [netnr.exe] C:\WINDOWS\system32\netnr.exe
O4 - HKLM\..\RunOnce: [msqf.exe] C:\WINDOWS\msqf.exe
O4 - HKLM\..\RunOnce: [ipvh32.exe] C:\WINDOWS\system32\ipvh32.exe
O4 - HKLM\..\RunOnce: [atllo32.exe] C:\WINDOWS\atllo32.exe
O4 - HKLM\..\RunOnce: [ieyq32.exe] C:\WINDOWS\ieyq32.exe
O4 - HKLM\..\RunOnce: [ieen.exe] C:\WINDOWS\system32\ieen.exe
O4 - HKLM\..\RunOnce: [sdkjh32.exe] C:\WINDOWS\system32\sdkjh32.exe
O4 - HKLM\..\RunOnce: [crip32.exe] C:\WINDOWS\crip32.exe
O4 - HKLM\..\RunOnce: [netor.exe] C:\WINDOWS\netor.exe
O4 - HKLM\..\RunOnce: [d3if32.exe] C:\WINDOWS\d3if32.exe
O4 - HKLM\..\RunOnce: [atlmp32.exe] C:\WINDOWS\system32\atlmp32.exe
O4 - HKLM\..\RunOnce: [atlux32.exe] C:\WINDOWS\system32\atlux32.exe
O4 - HKLM\..\RunOnce: [ntvx32.exe] C:\WINDOWS\ntvx32.exe
O4 - HKLM\..\RunOnce: [adddf32.exe] C:\WINDOWS\system32\adddf32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\system32\systa.exe
O4 - HKLM\..\RunOnce: [iedw32.exe] C:\WINDOWS\system32\iedw32.exe
O4 - HKLM\..\RunOnce: [syswp.exe] C:\WINDOWS\syswp.exe
O4 - HKLM\..\RunOnce: [atlal32.exe] C:\WINDOWS\system32\atlal32.exe
O4 - HKLM\..\RunOnce: [addku.exe] C:\WINDOWS\addku.exe
O4 - HKLM\..\RunOnce: [addpj32.exe] C:\WINDOWS\system32\addpj32.exe
O4 - HKLM\..\RunOnce: [addef32.exe] C:\WINDOWS\addef32.exe
O4 - HKLM\..\RunOnce: [crjk32.exe] C:\WINDOWS\crjk32.exe
O4 - HKLM\..\RunOnce: [appev32.exe] C:\WINDOWS\system32\appev32.exe
O4 - HKLM\..\RunOnce: [apiia.exe] C:\WINDOWS\system32\apiia.exe
O4 - HKLM\..\RunOnce: [atlra32.exe] C:\WINDOWS\atlra32.exe
O4 - HKLM\..\RunOnce: [ienb.exe] C:\WINDOWS\ienb.exe
O4 - HKLM\..\RunOnce: [atlgx.exe] C:\WINDOWS\system32\atlgx.exe
O4 - HKLM\..\RunOnce: [atlll.exe] C:\WINDOWS\system32\atlll.exe
O4 - HKLM\..\RunOnce: [adddk.exe] C:\WINDOWS\adddk.exe
O4 - HKLM\..\RunOnce: [ipek32.exe] C:\WINDOWS\system32\ipek32.exe
O4 - HKLM\..\RunOnce: [d3ol32.exe] C:\WINDOWS\system32\d3ol32.exe
O4 - HKLM\..\RunOnce: [mfcol32.exe] C:\WINDOWS\mfcol32.exe
O4 - HKLM\..\RunOnce: [apioz.exe] C:\WINDOWS\apioz.exe
O4 - HKLM\..\RunOnce: [netqs32.exe] C:\WINDOWS\netqs32.exe
O4 - HKLM\..\RunOnce: [syscl32.exe] C:\WINDOWS\system32\syscl32.exe
O4 - HKLM\..\RunOnce: [crpv32.exe] C:\WINDOWS\system32\crpv32.exe
O4 - HKLM\..\RunOnce: [ipfd32.exe] C:\WINDOWS\ipfd32.exe
O4 - HKLM\..\RunOnce: [ntnt.exe] C:\WINDOWS\ntnt.exe
O4 - HKLM\..\RunOnce: [netot.exe] C:\WINDOWS\system32\netot.exe
O4 - HKLM\..\RunOnce: [d3li32.exe] C:\WINDOWS\d3li32.exe
O4 - HKLM\..\RunOnce: [sysbq.exe] C:\WINDOWS\sysbq.exe
O4 - HKLM\..\RunOnce: [mfcxu32.exe] C:\WINDOWS\system32\mfcxu32.exe
O4 - HKLM\..\RunOnce: [addpu.exe] C:\WINDOWS\addpu.exe
O4 - HKLM\..\RunOnce: [ntpd.exe] C:\WINDOWS\ntpd.exe
O4 - HKLM\..\RunOnce: [winko.exe] C:\WINDOWS\system32\winko.exe
O4 - HKLM\..\RunOnce: [mszd.exe] C:\WINDOWS\system32\mszd.exe
O4 - HKLM\..\RunOnce: [ntkw32.exe] C:\WINDOWS\system32\ntkw32.exe
O4 - HKLM\..\RunOnce: [javadh32.exe] C:\WINDOWS\javadh32.exe
O4 - HKLM\..\RunOnce: [mfcil32.exe] C:\WINDOWS\mfcil32.exe
O4 - HKLM\..\RunOnce: [javadx.exe] C:\WINDOWS\javadx.exe
O4 - HKLM\..\RunOnce: [iphb.exe] C:\WINDOWS\system32\iphb.exe
O4 - HKLM\..\RunOnce: [mswq32.exe] C:\WINDOWS\mswq32.exe
O4 - HKLM\..\RunOnce: [winug.exe] C:\WINDOWS\winug.exe
O4 - HKLM\..\RunOnce: [mfcqc32.exe] C:\WINDOWS\system32\mfcqc32.exe
O4 - HKLM\..\RunOnce: [appak.exe] C:\WINDOWS\system32\appak.exe
O4 - HKLM\..\RunOnce: [appgz32.exe] C:\WINDOWS\system32\appgz32.exe
O4 - HKLM\..\RunOnce: [mswo32.exe] C:\WINDOWS\system32\mswo32.exe
O4 - HKLM\..\RunOnce: [appuw32.exe] C:\WINDOWS\appuw32.exe
O4 - HKLM\..\RunOnce: [ipeu.exe] C:\WINDOWS\system32\ipeu.exe
O4 - HKLM\..\RunOnce: [javaxv.exe] C:\WINDOWS\javaxv.exe
O4 - HKLM\..\RunOnce: [mfcwv32.exe] C:\WINDOWS\mfcwv32.exe
O4 - HKLM\..\RunOnce: [crck.exe] C:\WINDOWS\system32\crck.exe
O4 - HKLM\..\RunOnce: [msbz.exe] C:\WINDOWS\msbz.exe
O4 - HKLM\..\RunOnce: [mfced.exe] C:\WINDOWS\mfced.exe
O4 - HKLM\..\RunOnce: [addvu.exe] C:\WINDOWS\system32\addvu.exe
O4 - HKLM\..\RunOnce: [addms.exe] C:\WINDOWS\system32\addms.exe
O4 - HKLM\..\RunOnce: [crla32.exe] C:\WINDOWS\system32\crla32.exe
O4 - HKLM\..\RunOnce: [appzp32.exe] C:\WINDOWS\appzp32.exe
O4 - HKLM\..\RunOnce: [javazx.exe] C:\WINDOWS\system32\javazx.exe
O4 - HKLM\..\RunOnce: [ipdb.exe] C:\WINDOWS\ipdb.exe
O4 - HKLM\..\RunOnce: [d3ty32.exe] C:\WINDOWS\system32\d3ty32.exe
O4 - HKLM\..\RunOnce: [winjf32.exe] C:\WINDOWS\system32\winjf32.exe
O4 - HKLM\..\RunOnce: [ieej.exe] C:\WINDOWS\ieej.exe
O4 - HKLM\..\RunOnce: [ntdz32.exe] C:\WINDOWS\system32\ntdz32.exe
O4 - HKLM\..\RunOnce: [mfcbo32.exe] C:\WINDOWS\mfcbo32.exe
O4 - HKLM\..\RunOnce: [apibw.exe] C:\WINDOWS\apibw.exe
O4 - HKLM\..\RunOnce: [mfckx.exe] C:\WINDOWS\system32\mfckx.exe
O4 - HKLM\..\RunOnce: [sdkzu32.exe] C:\WINDOWS\sdkzu32.exe
O4 - HKLM\..\RunOnce: [mspb32.exe] C:\WINDOWS\mspb32.exe
O4 - HKLM\..\RunOnce: [crsf.exe] C:\WINDOWS\system32\crsf.exe
O4 - HKLM\..\RunOnce: [netrv32.exe] C:\WINDOWS\system32\netrv32.exe
O4 - HKLM\..\RunOnce: [addik32.exe] C:\WINDOWS\addik32.exe
O4 - HKLM\..\RunOnce: [appqs.exe] C:\WINDOWS\system32\appqs.exe
O4 - HKLM\..\RunOnce: [addqs.exe] C:\WINDOWS\addqs.exe
O4 - HKLM\..\RunOnce: [ipgq32.exe] C:\WINDOWS\system32\ipgq32.exe
O4 - HKLM\..\RunOnce: [d3qg32.exe] C:\WINDOWS\d3qg32.exe
O4 - HKLM\..\RunOnce: [appts32.exe] C:\WINDOWS\appts32.exe
O4 - HKLM\..\RunOnce: [apiyw.exe] C:\WINDOWS\system32\apiyw.exe
O4 - HKLM\..\RunOnce: [mfcgw32.exe] C:\WINDOWS\mfcgw32.exe
O4 - HKLM\..\RunOnce: [atlnt32.exe] C:\WINDOWS\system32\atlnt32.exe
O4 - HKLM\..\RunOnce: [mssx32.exe] C:\WINDOWS\system32\mssx32.exe
O4 - HKLM\..\RunOnce: [mfcvj32.exe] C:\WINDOWS\system32\mfcvj32.exe
O4 - HKLM\..\RunOnce: [ipzn.exe] C:\WINDOWS\ipzn.exe
O4 - HKLM\..\RunOnce: [apiao32.exe] C:\WINDOWS\system32\apiao32.exe
O4 - HKLM\..\RunOnce: [apipl.exe] C:\WINDOWS\apipl.exe
O4 - HKLM\..\RunOnce: [apiuz.exe] C:\WINDOWS\apiuz.exe
O4 - HKLM\..\RunOnce: [sysie.exe] C:\WINDOWS\system32\sysie.exe
O4 - HKLM\..\RunOnce: [netcp.exe] C:\WINDOWS\netcp.exe
O4 - HKLM\..\RunOnce: [mfcsw.exe] C:\WINDOWS\mfcsw.exe
O4 - HKLM\..\RunOnce: [addjv.exe] C:\WINDOWS\system32\addjv.exe
O4 - HKLM\..\RunOnce: [syscp32.exe] C:\WINDOWS\system32\syscp32.exe
O4 - HKLM\..\RunOnce: [winvi.exe] C:\WINDOWS\winvi.exe
O4 - HKLM\..\RunOnce: [mfcrm.exe] C:\WINDOWS\mfcrm.exe
O4 - HKLM\..\RunOnce: [javaew32.exe] C:\WINDOWS\javaew32.exe
O4 - HKLM\..\RunOnce: [apium32.exe] C:\WINDOWS\system32\apium32.exe
O4 - HKLM\..\RunOnce: [netuu32.exe] C:\WINDOWS\system32\netuu32.exe
O4 - HKLM\..\RunOnce: [netro32.exe] C:\WINDOWS\netro32.exe
O4 - HKLM\..\RunOnce: [apixl.exe] C:\WINDOWS\system32\apixl.exe
O4 - HKLM\..\RunOnce: [netli.exe] C:\WINDOWS\netli.exe
O4 - HKLM\..\RunOnce: [sysre.exe] C:\WINDOWS\system32\sysre.exe
O4 - HKLM\..\RunOnce: [iplq.exe] C:\WINDOWS\system32\iplq.exe
O4 - HKLM\..\RunOnce: [mfcaf.exe] C:\WINDOWS\mfcaf.exe
O4 - HKLM\..\RunOnce: [ipfh.exe] C:\WINDOWS\system32\ipfh.exe
O4 - HKLM\..\RunOnce: [mfcjl.exe] C:\WINDOWS\mfcjl.exe
O4 - HKLM\..\RunOnce: [sdkzi32.exe] C:\WINDOWS\system32\sdkzi32.exe
O4 - HKLM\..\RunOnce: [msxq32.exe] C:\WINDOWS\msxq32.exe
O4 - HKLM\..\RunOnce: [crsu.exe] C:\WINDOWS\crsu.exe
O4 - HKLM\..\RunOnce: [apirj32.exe] C:\WINDOWS\apirj32.exe
O4 - HKLM\..\RunOnce: [atlmv.exe] C:\WINDOWS\atlmv.exe
O4 - HKLM\..\RunOnce: [ield32.exe] C:\WINDOWS\ield32.exe
O4 - HKLM\..\RunOnce: [javajs.exe] C:\WINDOWS\system32\javajs.exe
O4 - HKLM\..\RunOnce: [mfcii32.exe] C:\WINDOWS\system32\mfcii32.exe
O4 - HKLM\..\RunOnce: [winyx32.exe] C:\WINDOWS\winyx32.exe
O4 - HKLM\..\RunOnce: [apilf32.exe] C:\WINDOWS\apilf32.exe
O4 - HKLM\..\RunOnce: [sdkzl.exe] C:\WINDOWS\sdkzl.exe
O4 - HKLM\..\RunOnce: [addgf.exe] C:\WINDOWS\addgf.exe
O4 - HKLM\..\RunOnce: [netur.exe] C:\WINDOWS\netur.exe
O4 - HKLM\..\RunOnce: [winhg.exe] C:\WINDOWS\system32\winhg.exe
O4 - HKLM\..\RunOnce: [apiwd32.exe] C:\WINDOWS\apiwd32.exe
O4 - HKLM\..\RunOnce: [sdkvk32.exe] C:\WINDOWS\sdkvk32.exe
O4 - HKLM\..\RunOnce: [syskx32.exe] C:\WINDOWS\system32\syskx32.exe
O4 - HKLM\..\RunOnce: [wineq.exe] C:\WINDOWS\wineq.exe
O4 - HKLM\..\RunOnce: [mfcau.exe] C:\WINDOWS\mfcau.exe
O4 - HKLM\..\RunOnce: [atlbu.exe] C:\WINDOWS\system32\atlbu.exe
O4 - HKLM\..\RunOnce: [msqu32.exe] C:\WINDOWS\system32\msqu32.exe
O4 - HKLM\..\RunOnce: [javarv32.exe] C:\WINDOWS\javarv32.exe
O4 - HKLM\..\RunOnce: [syscr.exe] C:\WINDOWS\system32\syscr.exe
O4 - HKLM\..\RunOnce: [addtb.exe] C:\WINDOWS\system32\addtb.exe
O4 - HKLM\..\RunOnce: [sdkwi32.exe] C:\WINDOWS\system32\sdkwi32.exe
O4 - HKLM\..\RunOnce: [sysub32.exe] C:\WINDOWS\sysub32.exe
O4 - HKLM\..\RunOnce: [sysiy32.exe] C:\WINDOWS\system32\sysiy32.exe
O4 - HKLM\..\RunOnce: [sdknu32.exe] C:\WINDOWS\system32\sdknu32.exe
O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe
O4 - HKLM\..\RunOnce: [appkd32.exe] C:\WINDOWS\system32\appkd32.exe
O4 - HKLM\..\RunOnce: [ntjw.exe] C:\WINDOWS\ntjw.exe
O4 - HKLM\..\RunOnce: [netoh32.exe] C:\WINDOWS\netoh32.exe
O4 - HKLM\..\RunOnce: [windf.exe] C:\WINDOWS\system32\windf.exe
O4 - HKLM\..\RunOnce: [sdkqu.exe] C:\WINDOWS\system32\sdkqu.exe
O4 - HKLM\..\RunOnce: [ntmj32.exe] C:\WINDOWS\ntmj32.exe
O4 - HKLM\..\RunOnce: [ielc32.exe] C:\WINDOWS\system32\ielc32.exe
O4 - HKLM\..\RunOnce: [javaws.exe] C:\WINDOWS\javaws.exe
O4 - HKLM\..\RunOnce: [mfcpj32.exe] C:\WINDOWS\system32\mfcpj32.exe
O4 - HKLM\..\RunOnce: [sysoz32.exe] C:\WINDOWS\sysoz32.exe
O4 - HKLM\..\RunOnce: [ievt.exe] C:\WINDOWS\ievt.exe
O4 - HKLM\..\RunOnce: [ntnb32.exe] C:\WINDOWS\system32\ntnb32.exe
O4 - HKLM\..\RunOnce: [winnh.exe] C:\WINDOWS\winnh.exe
O4 - HKLM\..\RunOnce: [syswh.exe] C:\WINDOWS\system32\syswh.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [WinMem] C:\Program Files\blcorp\UWCSuite\WinMem\WinMem.exe
O4 - HKCU\..\Run: [SSS6_SPM] "C:\Program Files\Steganos Security Suite 6\spm.exe" /booting
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\system32\hookdump.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Startup: Freeserve Connection Kit.lnk = C:\freeserve\freeserveconnectionkit\atdialler1.exe
O4 - Startup: IC Task Manager.lnk = C:\Program Files\Aladdin Systems\Internet Cleanup\onictask.exe
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Startup: MRU-Blaster Scheduler.lnk = C:\Program Files\MRU-Blaster\scheduler.exe
O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: ChatSpace Full Java Client 3.1.0.229 - http://surechat.com:...va/cfs31229.cab
O16 - DPF: ChatSpace Full Java Client 3.1.0.245 - http://chat-a3.frees...va/cfs31245.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-18.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by101fd.bay10...es/MsnPUpld.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://G:\system\intralaunch.CAB
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ol_v1-0-3-0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crsv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE81.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe